Description
Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A heap‑based buffer overflow in the Windows Storage Port Driver can be triggered by an attacker who has local access to the system. The flaw arises when the driver mishandles heap allocations, allowing unintended memory overwrite and the execution of code with higher privilege levels. This escalation permits unauthorized configuration changes, data theft, or the installation of additional malware.

Affected Systems

The vulnerability impacts Microsoft Windows 11 versions 24H2, 25H2 and 26H1, as well as Windows Server 2025, including Server Core installations.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity local privilege escalation. While the EPSS score is < 1% and the flaw is not listed in CISA KEV, the lack of widespread exploitation data does not reduce the risk to environments where local users can write to the driver. The attack vector is local; an authorized or compromised local user must trigger the overflow to gain elevated administrative rights. No additional conditions are noted beyond local access.

Generated by OpenCVE AI on September 10, 2026 at 00:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows security update addressing the Storage Port Driver buffer overflow.
  • Restrict local user privileges by enforcing least privilege principles and limiting accounts that can load or execute storage drivers.
  • If the driver is not required for business operations, disable or remove it and enforce Windows Defender Application Control policies to block unauthorized execution of the driver.

Generated by OpenCVE AI on September 10, 2026 at 00:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.
Title Microsoft Storage Port Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:33.941Z

Reserved: 2026-08-10T18:14:23.517Z

Link: CVE-2026-72946

cve-icon Vulnrichment

Updated: 2026-09-11T14:55:54.873Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:19.893

Modified: 2026-09-22T13:56:23.913

Link: CVE-2026-72946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:07:32Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow